BreakMesh – Vulnerability Simulator & Cyber Range
Documentation / Overview

BreakMesh documentation

Security testing documentation built around authorization, coverage and evidence.

Learn how to authorize targets, choose an assessment workflow, understand scanner safeguards, interpret reports and use BreakMesh responsibly.

Start here

01
Quick startAdd an authorized target, complete the applicable authorization workflow and run your first standard assessment.
02
Authorization modelUnderstand verified domains, explicit consent, read-only credentials, uploaded artifacts and Active Pentest SOW/RoE.
03
Scanner safetyReview scope, network, concurrency, cooldown and active-testing safeguards.
04
Reports & evidenceUnderstand severity, confidence, evidence snippets, remediation and available report exports.

Assessment families

Standard security & assurance10 packages and 102 security & assurance checks across supported surfaces.
Automated Active Pentest12 Basic + 9 Advanced automated active probes under signed authorization.
Cloud PostureSelected read-only AWS, Azure and GCP configuration checks.
AI & MobileConsent-gated text-only AI canaries and offline uploaded APK/IPA analysis.
Documentation / Start here / Quick start

Getting started

Run your first authorized standard assessment.

Start with Basic Hygiene on a verified website, then add other assessment packages as your environment and authorization needs expand.

Standard website workflow

01
Create an accountUse the BreakMesh signup flow.
02
Add the targetAdd a website or application domain you are authorized to assess.
03
Verify domain controlUse the DNS TXT value provided in the product. Do not invent or reuse a verification token.
04
Choose Basic HygieneThe free baseline currently contains 15 checks.
05
Review resultsUse severity, confidence, evidence and remediation guidance to prioritize follow-up.
i
Other workflows differ

Cloud, AI, mobile and Active Pentest use their own authorization models rather than this DNS-only workflow.

Documentation / Start here / Authorization model

Authorization

Different assessments require different authorization.

BreakMesh uses authorization appropriate to each assessment workflow rather than a single universal mechanism.

Authorization types

Verified domainDomain-based website and application assessments.
Explicit consentSelected interactive, credentialed and AI canary checks.
Read-only credentialsSupported cloud-posture workflows.
Uploaded artifactMobile APK/IPA static analysis.
Signed SOW + RoEAutomated Active Pentest engagements.

Customer authorization responsibility

Customers should only add systems they own, operate or are explicitly authorized to test. Verification is a product safeguard; it does not replace the customer's responsibility to have permission to assess the target.

Documentation / Safety & governance / Scanner Safety & Authorization

Safety & governance

Scanner Safety & Authorization

How BreakMesh keeps standard assessments scoped, controlled and authorized — and how the safety model changes for cloud, AI, mobile and automated Active Pentest workflows.

01
Authorization before assessmentDomain verification, explicit consent, read-only credentials, uploaded artifacts or signed SOW + RoE depending on workflow.
02
Scope boundariesStandard domain requests stay constrained to approved targets and do not follow off-scope domains.
03
Network safeguardsPrivate, localhost, link-local and metadata endpoints are blocked in the standard scanner workflow.
04
Separate active-testing modeActive Pentest uses controlled exploitation only inside a signed, time-bounded engagement with additional safeguards.
!
Avoid absolute “production-safe” claims

BreakMesh uses “designed to minimize production impact” and “non-destructive by default” rather than promising that security testing can never affect a target.

Safety principles

BreakMesh uses different controls for different assessment types. A domain-based website assessment is not authorized the same way as a read-only cloud assessment, an uploaded mobile artifact, an approved AI endpoint or an Active Pentest engagement.

Verified domainDomain-based web and application assessments.
Explicit consentSelected interactive, credentialed and AI canary workflows.
Read-only credentialsSupported AWS, Azure and GCP posture checks.
Uploaded artifactOffline APK / IPA static analysis.
Signed SOW + RoERequired before automated Active Pentest probes run.

Standard assessment mode

Standard security and assurance packages are designed around reading, observing and controlled requests rather than destructive exploitation, and are kept separate from Active Pentest in the product catalogue.

ControlWhat it doesWhy it matters
Verified targetDomain-based assessments require target verification before the scanner runs.Keeps standard web testing tied to an approved target.
Redirect boundaryStandard scanner requests do not follow redirects to off-scope domains.Reduces accidental testing outside the approved domain scope.
Private-network blockingPrivate, local, link-local and metadata endpoints are blocked in the standard scanner workflow.Reduces SSRF-style internal-network abuse.
Concurrency controlConcurrent execution is controlled rather than allowed to grow without bound.Helps limit unnecessary target load.
Cooldown controlRepeated scan starts are subject to cooldown controls.Helps reduce repeated bursts against the same target or organization.

Network and redirect boundaries

Scanner requests are constrained to verified targets and do not follow off-scope domains. Private, local, link-local and metadata endpoints are blocked.

Concurrency, cooldowns and request limits

Concurrency and cooldown controls help prevent repeated scan starts from overwhelming a target or organization.

  • Concurrent execution is controlled to reduce unnecessary load.
  • Repeated scan starts are subject to cooldown controls.
  • Assessment requests use bounded execution behavior rather than unrestricted traffic generation.

Specialized assessment workflows

Cloud Posture

Cloud Posture uses authorized read-only AWS, Azure and GCP configuration checks for selected public exposure, network, IAM, logging and encryption risks. Cloud authorization is credential-based rather than DNS-based.

Recommended cloud language

“Use credentials with the minimum read-only permissions required for the supported checks. Do not grant BreakMesh write or administrative permissions.”

AI Security

AI Security uses consent-gated, controlled text-only canary probes against approved LLM or chat interfaces.

  • Require explicit consent for the approved AI endpoint.
  • Use controlled text-only canary probes for the documented AI Security workflow.
  • Disable tool-calling or real-world agentic actions during the assessment.
  • Do not describe canary probes as “harmless” or guarantee zero impact.

Mobile Static Analysis

Mobile Static Analysis is an offline analysis workflow for an uploaded APK/IPA file — the artifact is analyzed without interacting with the live mobile application service.

Automated Active Pentest safety model

Active Pentest is separate from standard assessment mode. It uses consent-gated automated active probes for selected vulnerability classes and requires a stronger authorization and execution model.

01
Approve the target and engagementConfirm the target is authorized for active testing.
02
Sign SOW + Rules of EngagementDefine scope, testing window and engagement constraints before probes can run.
03
Lock scope and limitsApply approved target, URL, duration and probe-count limits.
04
Execute automated active probesBreakMesh runs the authorized Basic or Advanced probe set without a human pentester manually executing the assessment.
05
Capture evidence and allow emergency pauseUse request/response evidence, supported OAST confirmation and emergency stopping controls.
Pentest Basic12 automated active probes across selected OWASP A01–A07 vulnerability classes.
Pentest Advanced9 additional automated probes for selected server-side, upload, deserialization and business-logic classes.
Engagement governanceApproved scope + time window + SOW/RoE + emergency pause.

What BreakMesh does not promise

BreakMesh documents product boundaries alongside its safeguards.

AvoidUse instead
“100% safe”“Designed to minimize production impact.”
“Cannot affect production”“Uses controlled, non-destructive standard checks and request controls.”
“Every check is non-destructive”“All standard package checks are designed to be non-destructive; Active Pentest is separate.”
“DNS verification before every assessment”“Domain-based testing uses verification; other workflows use appropriate authorization.”
“BreakMesh proves compliance”“BreakMesh can provide selected evidence and evidence mapping for reviews.”
“Automated Pentest replaces every human pentest”“Automated active validation for the supported probe classes.”

If you need to stop testing

Use the following operational path when testing needs to be stopped.

  1. For Active Pentest, use the emergency pause control available to the engagement.
  2. For scheduled standard assessments, pause or disable the relevant schedule in the product.
  3. Contact BreakMesh support if unexpected target behavior continues after testing stops.

Customer responsibility

BreakMesh must only be used on systems the customer owns, operates or is explicitly authorized to test. Customers remain responsible for complying with client agreements, platform policies and applicable law.

Users should not attempt to bypass scope controls or use BreakMesh findings for unauthorized activity.

Documentation / Safety & governance / Responsible Use

Policy

Responsible Use

BreakMesh is for authorized security assessment, remediation tracking and approved security-review workflows.

Authorized targets only

Do not add or assess targets without permission from the owner or operator.

Users are responsible for ensuring assessments comply with client agreements, platform policies and applicable law.

Responsible operation

  • Use the platform for security hygiene, authorized reviews, remediation validation and approved evidence collection.
  • Do not attempt to bypass scope, authorization or network safeguards.
  • Do not use findings or product access to facilitate unauthorized activity.
  • Use Active Pentest only under the signed engagement scope and Rules of Engagement.
Documentation / Safety & governance / Active Pentest Safety

Automated active testing

Active Pentest Authorization & Safety

BreakMesh Active Pentest is a fully automated testing mode with 12 Basic and 9 additional Advanced active probes. It is separate from standard non-destructive assessment mode.

!
Fully automated

No human pentester manually executes the supported Basic or Advanced probe set.

Before probes run

  • Approved target and engagement.
  • Signed Statement of Work and Rules of Engagement.
  • Defined testing window.
  • Defined target, URL, duration and probe-count limits.

Pentest Basic — 12 automated active probes

Covering selected vulnerability classes including:

  • SQL Injection (Error-Based)
  • SQL Injection (Boolean-Blind)
  • XSS — Reflected
  • XSS — Stored
  • XXE Injection
  • Path Traversal
  • Open Redirect (Active)
  • Auth Bypass Probes
  • IDOR (Two-Account)
  • Broken Function Auth (Active)
  • HTTP Parameter Pollution (HPP)
  • NoSQL Injection

Pentest Advanced — 9 additional automated active probes

Extending Basic with:

  • Command Injection (Timing)
  • SSRF (Callback)
  • Header Injection
  • File Upload Bypass
  • API Mass Assignment
  • Insecure Deserialization (Timing)
  • Business Logic — Price Manipulation
  • HTTP Request Smuggling / Desync Readiness
  • Web Cache Poisoning Readiness

Execution controls

01
Hard scope enforcementActive requests remain within the approved engagement boundaries.
02
Request budgetsActive execution is bounded rather than open-ended.
03
Emergency pauseThe engagement can be stopped through the active-testing pause control.
04
Automated executionNo human pentester manually executes the supported Basic or Advanced probe set.
  • Signed SOW + Rules of Engagement
  • Explicit customer consent
  • Approved testing window
  • Hard URL scope enforcement
  • Per-scan request budget
  • Target-specific engagement
  • Emergency pause
  • Destructive payload restrictions
  • Traceable assessment record

Product boundary

BreakMesh provides automated active validation for the supported probe classes. Some customer contracts, assurance programs or complex applications may still require broader human-led exploratory testing. It should not be described as a universal replacement for every human-led exploratory penetration test or customer-mandated manual assessment.

Documentation / Assessment types / Standard assessments

Coverage

Standard security & assurance assessments

BreakMesh groups 102 security & assurance checks into 10 standard packages.

Basic Hygiene · 15Headers, HTTPS, TLS, cookies, server disclosure, and exposure checks.
OWASP Starter · 14CORS, CSP, source maps, open redirects, directory listings, and sensitive files.
Threat Readiness · 8WAF/CDN, bot, rate-limit, DDoS readiness, and origin exposure signals.
Auth & Session · 16Login, reset, rate-limit, enumeration, and session cookie checks.
API Security · 16API docs, auth signals, CORS, rate limits, JWT analysis, GraphQL, shadow API, and leakage checks.
Compliance Evidence · 10Security contact, privacy policy, and terms evidence checks.
Cloud Posture · 10Read-only AWS/Azure/GCP checks: public storage exposure, open security-group/firewall ingress, and stale IAM credentials.
AI Security · 10Safe canary probes for applications with LLM or AI chat interfaces.
Mobile Static Analysis · 1Offline static analysis of an uploaded Android APK or iOS IPA: hardcoded secrets, ATS/cleartext-traffic misconfiguration, insecure storage flags, and sensitive permission review. Zero network traffic — the artifact is inspected entirely offline.
Web Quality Evidence · 2Accessibility, SEO, social, and digital-readiness evidence snapshots.
Documentation / Assessment types / Cloud Posture

Read-only cloud checks

Cloud Posture

Authorized read-only AWS, Azure and GCP configuration checks for selected exposure, network, IAM, logging and encryption risks.

Authorization

Use credentials with the minimum read-only permissions necessary for the supported checks. Do not provide write or administrative access. Credentials are used only for the duration of the scan and are never stored.

Selected coverage

  • Public storage exposure
  • Open ingress rules
  • IAM risks
  • Logging gaps
  • Encryption configuration
  • AWS public S3 storage exposure, open security groups, stale access keys, overly permissive IAM, CloudTrail and encryption gaps.
  • Azure public blob exposure and open NSG ingress.
  • GCP public Cloud Storage exposure and open VPC firewall ingress.
Documentation / Assessment types / AI Security

Consent-gated AI assessment

AI Security

Controlled, text-only canary probes for approved LLM and AI chat interfaces.

Assessment controls

  • Explicit consent is required.
  • The documented workflow uses controlled text-only canary probes.
  • Testing is limited to the approved LLM / chat interface only.
  • Tool-calling should be disabled during the assessment.
  • Real-world agentic actions should be disabled during the assessment.

Selected indicators

Endpoint discovery, prompt reflection, system-prompt exposure, prompt-injection indicators, response-data leakage, rate-limit readiness, training/model extraction indicators, moderation-bypass canaries and jailbreak-pattern indicators.

Documentation / Assessment types / Mobile Static Analysis

Offline artifact analysis

Mobile Static Analysis

Upload an Android APK or iOS IPA for offline static analysis of selected application-security indicators.

Safety model

The uploaded artifact is analyzed without interacting with the live mobile application service.

Selected analysis areas

  • Embedded secrets
  • Transport security
  • Insecure storage
  • Exported components
  • Sensitive permissions
Documentation / Results & workflows / Reports & evidence

Results

Reports & evidence

BreakMesh findings are designed to connect technical observations to remediation and evidence workflows.

Finding model

Findings include severity, confidence, supporting evidence and remediation guidance.

Exports

JSON reports are available on eligible plans, with PDF and white-label PDF reporting available according to the selected plan.

Compliance evidence

!
Evidence mapping does not certify compliance

BreakMesh can map selected findings to compliance-control evidence. Compliance/evidence mapping does not certify compliance.

Documentation / Results & workflows / API & webhooks

Automation

API & webhooks

BreakMesh supports API key access and signed outbound webhooks on eligible plans.

What this covers

  • Authentication model and key creation.
  • Key rotation and revocation.
  • Webhook signature verification.
  • Supported event types.
  • Retry behavior and delivery guarantees.
  • Rate limits and error formats.

A full interactive API reference is not yet published — this section will link out to it once it's ready.

Documentation / Results & workflows / Usage & package runs

Usage model

Package runs

One package run means one selected standard scanner package executed against one target.

Example

10 standard packages 10 targets 100 package runs

Package runs apply to standard security and assurance workflows. Active Pentest is an authorized engagement and is not treated as a normal standard package run.

Documentation / Reference / Glossary

Reference

Glossary

Terminology used across BreakMesh's product, reports and pricing.

Assessments & scope

TermDefinition
TargetA website, application, API, cloud account, AI endpoint or mobile artifact added for assessment.
Verified target / verified domainA domain-based target that has completed DNS TXT record verification.
DNS TXT verificationThe domain-ownership check performed by adding a BreakMesh-issued token to the target's DNS records.
Explicit consentAuthorization method used for selected interactive, credentialed and AI canary workflows.
Read-only credentialsCloud provider credentials, scoped to read-only access, used for Cloud Posture checks.
Uploaded artifactAn APK or IPA file submitted for Mobile Static Analysis.
PackageA named group of related checks (e.g. Basic Hygiene, OWASP Starter) run together against a target.
CheckOne individual test performed within a package.
Package runOne selected standard scanner package executed against one target — the platform's billable usage unit for standard assessments.
ScanOne execution of a package against a target, producing a report.
Attack surfaceThe set of discovered URLs, parameters and forms a scan can probe on a target.
ScopeThe approved boundary (targets, URLs) an assessment is restricted to.
CooldownA minimum wait period enforced between repeated scan starts on the same target.
Concurrency controlA limit on how many scans can run at once for an organization.
Non-destructiveDescribes standard package checks: read/observe/controlled-request behavior that avoids exploitation or data modification.
Consent-gatedA check or probe that only runs after the customer has explicitly authorized it.
Canary probeA controlled, distinctive test payload (e.g. in AI Security) used to detect a specific behavior without real exploitation.

Active Pentest

TermDefinition
Active probeOne consent-gated, automated exploitation attempt run as part of an Active Pentest engagement — not a standard check.
EngagementA signed, time-bounded, scope-locked Active Pentest authorization (SOW + Rules of Engagement).
SOWStatement of Work — defines the approved Active Pentest engagement.
RoERules of Engagement — defines scope and operating constraints for active testing.
Emergency pauseA control that immediately stops an in-progress Active Pentest engagement.
Request budgetThe bounded number of requests an Active Pentest engagement is allowed to issue.
OASTOut-of-band Application Security Testing — callback-based confirmation used by selected probes (e.g. SSRF).
PoC (Proof of Concept)The captured request/response evidence attached to a confirmed Active Pentest finding.
Confirmed exploitA finding actively verified (not just inferred) during an Active Pentest engagement.

Findings & reports

TermDefinition
FindingA single reported issue produced by a check or probe.
SeverityHow serious a finding is: Critical, High, Medium, Low or Informational.
ConfidenceHow certain BreakMesh is that a finding is real: Confirmed, Indicative or Informational.
Risk scoreA 0–100 score summarizing a scan's overall risk based on its findings.
GradeA letter (A–F) derived from the risk score and check coverage.
Risk levelA plain-language band (Clear, Low, Medium, High, Critical) derived from the risk score.
Coverage ratioThe share of a package's checks that produced a definitive pass/fail result (used to cap the grade when many checks were inconclusive).
RemediationThe recommended fix guidance attached to a finding.
EvidenceThe supporting data (headers, response snippets, records) captured alongside a finding.
CVSSCommon Vulnerability Scoring System — a severity score attached to confirmed Active Pentest findings.
CVSS vectorThe structured string encoding how a CVSS score was derived.
Triage statusThe review state of a finding: pending review, verified or false positive.
Suppressed findingA finding manually marked as a false positive and excluded from report counts.
Evidence mappingLinking selected technical findings to relevant compliance-control evidence; not a compliance certification.
SOC 2 Trust Services CategoryOne of the five SOC 2 evidence categories BreakMesh maps findings to: Security, Availability, Confidentiality, Processing Integrity, Privacy.
Compliance frameworkAn external standard (SOC 2, PCI-DSS, ISO/IEC 27001, HIPAA Security Rule) that selected findings can be mapped to as evidence.
White-label reportA PDF report re-branded with an agency's own name and logo instead of BreakMesh's.

Account, plans & billing

TermDefinition
Plan tierThe subscription level for an organization: Free, Developer, Team, Business, Agency or Enterprise.
OrganizationThe billing and access-control unit a BreakMesh account belongs to.
Client profileAn agency's saved client record used to group targets and apply white-label branding.
AgencyA BreakMesh customer that manages assessments and reporting on behalf of multiple clients.
API keyA credential used to authenticate programmatic access to the BreakMesh API.
WebhookA signed outbound HTTP notification BreakMesh sends when a scan or subscription event occurs.
Wallet balance / prepaid creditA pay-as-you-go balance that funds package runs outside a subscription's included quota.
MFAMulti-factor authentication, available for account and admin login.
DPAData Processing Agreement, available for customers who need one for their own compliance program.